The platforms infected thousands of internet-connected devices worldwide to conceal cyberattacks against HHS, NIH, and other US targets.
The Justice Department and Federal Bureau of Investigation (FBI) announced court-authorized domain seizures to deny cyber actors access to two hacking platforms, known as QScan and QTRouter, used to target US critical infrastructure and sensitive networks.
According to court documents, the platforms were operated by a Peopleโs Republic of China (PRC) state-sponsored group known as QTFY. Victims of the intrusion activity include the Department of Health and Human Services, the National Institutes of Health, the Department of Energy, and the Federal Reserve.
โState-sponsored malicious hackers preying on Americaโs critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,โ says Todd Blanche, attorney general, in a release.
How the Hacking Platforms Functioned
The hacking tools worked in conjunction to scan and automatically infect thousands of internet-of-things devices worldwide. These compromised devices were added to a network that allowed actors to conceal the origin of their computer intrusion activities. Malicious communications appeared to originate from the infected devices, which were often local to the targeted networks.
โToday we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure,โ says FBI director Kash Patel in a release. โThese tools were used by PRC cyber actors to hide the origin of their attacks.โ
Because the seized domains were hard-coded into the malware for communication and authentication, the court-authorized seizures rendered the platforms inoperable.
Broader Context of Cyber Operations
This disruption is part of a series of technical operations against hacking activities. In 2024, the FBI disabled a botnet of hundreds of thousands of infected internet-of-things devices provided by the group Flax Typhoon. In 2023, authorities disrupted a botnet used by the group Volt Typhoon to conceal the exploitation of critical infrastructure.
โTodayโs announcement demonstrates the Justice Departmentโs steadfast commitment to going on the offensive against cyber threats to the national security,โ says John A Eisenberg, assistant attorney general for national security, in a release.
The FBI and the National Security Agency also published a cybersecurity advisory providing indicators of compromise related to QTFY activity dating back to 2018. Additionally, Lumen Technologiesโ threat intelligence group, Black Lotus Labs, published a description of the group’s tactics, techniques, and procedures.
IDย 165351352ย ยฉย Jiawangkunย |ย Dreamstime.com